2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-31176MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31174MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31172MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31171MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31165MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31164MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31160MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31159MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-41240MEDIUM6.1DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an incons...
CVE-2026-41239MEDIUM6.8DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior t...
CVE-2026-41238MEDIUM6.9DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulne...
CVE-2026-39087MEDIUM6.4ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.
CVE-2026-31531MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv4: nexthop: allocate skb dynamically in rtm_get_...
CVE-2026-28040MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Ta...
CVE-2026-4106MEDIUM5.3The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some P...
CVE-2026-41990MEDIUM4Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attack...
CVE-2026-41989MEDIUM6.7Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext ...
CVE-2026-41233MEDIUM5.4Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` paramet...
CVE-2026-41232MEDIUM5Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain owner...
CVE-2026-40529MEDIUM5.1CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be ...
CVE-2026-3361MEDIUM6.4The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta ...
CVE-2026-3007MEDIUM5.4Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitr...
CVE-2026-2951MEDIUM5.4The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-41243MEDIUM5.4OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `saf...
CVE-2026-41182MEDIUM5.3LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScri...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now